Self-hosted · Slack-native · Audit-first

Know who has access.
And why.

BigBrotherBot turns every access request into a risk-scored, policy-checked, fully-audited decision — without anyone leaving Slack. Runs on your infrastructure. Licensed per seat.

Your data never leaves your infra Every decision audited Deploys in an afternoon
Self-hosted RBAC & audit trail Slack-native Risk-scored Drift detection
What it does

Access governance, end to end

One bot covers the whole lifecycle — from the request in Slack to the audit row your auditor reads a year later.

Slack-native requests

Users run /request-access and approvers decide right in Slack. No new portal, no context-switch, no email chain.

Risk-based tiered approval

Every request is scored on sensitivity, first-time privilege, and more. Low risk auto-approves; high risk steps up to extra reviewers.

Separation of Duties always free

Define toxic combinations once. BBB flags conflicting grants before they're approved — not in next quarter's audit.

JIT access checkout

Grants are time-boxed by default. Access checks out for the window it's needed and expires on its own — no standing privilege left behind.

Approve with modifications

Approvers don't have to accept a request as-is. Change the role or shorten the expiry at decision time, then approve in one step.

Integration drift detection

Sync real access across your integrations — GitHub, GitLab, Google Workspace, Metabase, Vanta, Wizer and many more. Mismatches land in a triage queue for one-click remediation.

Automated on/offboarding

Hire and termination events drive boarding checklists automatically, with SCIM 2.0 inbound provisioning from your IdP. One authoritative source deactivates users — the rest just observe.

On-call schedules

An RRULE rotation engine resolves who's on-call now and syncs Slack usergroups to match. Escalation policies, PTO auto-cover and handoff reports come built in — no separate paging tool.

Recertification & compliance always free

Periodic access reviews, training campaigns and certification evidence — kept and retained so audits become a query, not a fire drill.

Help Desk module add-on

A full ticketing desk in Slack: SLA tiers, CSAT surveys, a knowledge base for deflection and round-robin assignment across your team.

Synthetic monitoring add-on

Probe your services on a schedule — HTTP, TLS and journey checks feed a public status page and fire alerts the moment an SLO slips.

Automations & GitOps

Wire up policies in a visual flow builder, or manage them as code. Export your config, review the plan, and apply it — GitOps for access.


How it works

Three steps, zero spreadsheets

From request to provisioned-and-audited — most of it without a human in the loop.

1

Request in Slack

Someone runs /request-access, picks a service and gives a reason. That's the whole user experience.

2

Scored & routed

BBB scores the risk, checks separation-of-duties, and routes to the right approvers — or auto-approves when policy allows.

3

Approved & audited

The decision is recorded, the requester is notified, and the grant is tracked against what your integrations actually show.

Risk engine

Spend reviewer time where it matters

Not every request needs a human. BBB scores each one and lets the routine ones through, so approvers only see what's actually risky.

  • Auto-approve low-risk, repeat-pattern requests
  • Step up high-sensitivity or first-time-privileged grants
  • Critical-tier vetoes can never silently auto-approve
Read-only dashboard · repeatauto · score 12
Staging deploy accessauto · score 28
Production DB · high sensitivity72
→ step-up: 2 approvers + SoDHIGH
Reality vs intent

Catch the access you didn't grant

BBB syncs what your integrations actually show and compares it to what was approved. When the two diverge, you hear about it.

  • Removed externally — granted in BBB, gone upstream
  • Role mismatch — observed role ≠ the role you approved
  • Unlinked external members surfaced for review
github · @ravi → adminrole mismatch
gworkspace · @meiremoved upstream
wizer · @sol → analystin sync
unknown@vendor.comunlinked

Security & trust

Your bot. Your infra. Your data.

BigBrotherBot is not a SaaS. You run it inside your own environment, so the most sensitive thing it touches — who can access what — never leaves your control.

Self-hosted by design

Ships as a single Go service plus PostgreSQL. Deploy it on your Kubernetes, your VPC, your rules.

Verified Slack requests

Every Slack webhook is signature-verified. Trusted-proxy handling keeps client IPs honest behind your load balancer.

Role-based access control

Five roles and scoped permissions gate every admin action. Auth via Google OAuth or local password (bcrypt, cost 12).

Immutable audit log

Grants, denials, revokes, deletes and config changes are all recorded with retention controls for compliance evidence.

Least access for the bot too

Integrations use narrowly-scoped credentials and per-source lifecycle authority — only one source may deactivate a user.

Rate-limited & bounded

Per-user rate limiting, request-body limits and CSRF protection on the admin surface — sane defaults, configurable.


Pricing

Free to start. Per seat when you scale.

Community is free forever — up to 10 seats, with compliance and separation-of-duties checks free for everyone. Team and Enterprise add integrations, provisioning and more, licensed per seat.

Community
Free · up to 10 seats

Compliance & SoD checks are free for everyone, forever. Self-hosted, air-gap friendly, no phone-home.

See pricing

FAQ

Questions, answered

The things teams ask before they deploy.

Is BigBrotherBot self-hosted or SaaS?

Self-hosted. It ships as a single Go service plus PostgreSQL and runs entirely inside your own infrastructure — the access data it processes never leaves your environment.

How is BigBrotherBot licensed?

Per active seat. Community is free forever up to 10 seats; Team and Enterprise are licensed per active seat and billed annually. Licenses are offline signed keys — air-gap friendly, no phone-home.

Do I need a credit card to try it?

No. The free trial runs for 30 days with every feature and unlimited seats, and requires no credit card.

Which integrations does BigBrotherBot support?

Drivers for GitHub, GitLab, Google Workspace, Slack, Jira, Metabase, Sentry, Cloudflare, Vanta, Wizer and more sync real access to detect drift. See the integrations page for the full list.

How long does deployment take?

Most teams deploy in an afternoon — one container plus PostgreSQL on your Kubernetes or VPC. The quickstart walks through it.

Ready to see who has access?

Book a 20-minute walkthrough. We'll show you a real request flow, from Slack command to audit row.

Start free trial Request a demo